Opened 3 years ago

Closed 2 years ago

#15654 closed enhancement (fixed)

grilo-0.3.14

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: gnome-41
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version,

Change History (7)

comment:1 by Douglas R. Reno, 3 years ago

Priority: normalelevated

Marking as elevated due to CVE-2016-20011: "Fix TLS cert validation not being done for any network call" - as the description states, no validation of certificates were performed, even when TLS was requested.

comment:2 by Xi Ruoyao, 3 years ago

Test suite needs "mkdir /usr/lib/grilo-0.3" for some reason.

comment:3 by Douglas R. Reno, 2 years ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:4 by Douglas R. Reno, 2 years ago

NEW in 0.3.14
=============
  * !78 CVE-2016-20011: Fix TLS cert validation not being done for any network call
  * !80 Fix double-free when using GrlNet in Python
  * !71 Load config from GRL_CONFIG_PATH if set
  * !77 Clarify LGPLv2.1 or later license
  * !70 Handle numeric limits for GrlOperationOptions

comment:5 by Douglas R. Reno, 2 years ago

The actual CVE number for grilo is CVE-2021-39365 (CVE-2016-20011 is for libgrss).

comment:7 by Douglas R. Reno, 2 years ago

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.